Level 2 — Security Introduction and Attack Skill Basics
-
Step 96. Bandit 0–5 — The Wargame Solving Cycle
Step 96. Bandit 0–5 — The Wargame Solving Cycle Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2.5 hours Prerequisites: Level 1 complete. You’ve connected…
-
Step 97. Bandit 6~10 — Mastering Conditional Searches with find
Step 97. Bandit 6~10 — Mastering Conditional Searches with find Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: you’ve finished the…
-
Step 98. Bandit 11~15 — Encoding and Network Connections
Step 98. Bandit 11~15 — Encoding and Network Connections Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 3 hours Prerequisites: you’ve finished the solving…
-
Step 99. Bandit 16~20 — First Encounter with setuid
Step 99. Bandit 16~20 — First Encounter with setuid Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: you’ve finished the find…
-
Step 100. Bandit 21~25 — The cron Exploitation Mindset
Step 100. Bandit 21~25 — The cron Exploitation Mindset Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: you’ve finished setuid and…
-
Step 101. Bandit 26~30 — Digging Secrets from git History, and the Finish Line
Step 101. Bandit 26~30 — Digging Secrets from git History, and the Finish Line Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours…
-
Step 102. Natas 0~5 — Opening the Door to Web Wargames
Step 102. Natas 0~5 — Opening the Door to Web Wargames Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 3 hours Prerequisites: you’ll use…
-
Step 103. Natas 6~10 — Reading Server Code and Command Injection
Step 103. Natas 6~10 — Reading Server Code and Command Injection Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: you’ll use…
-
Step 104. Natas 11~15 — XOR Analysis and Your First SQL Injection
Step 104. Natas 11~15 — XOR Analysis and Your First SQL Injection Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3.5 hours Prerequisites: the…
-
Step 105. ★ Review — Cataloging Wargame Techniques
Step 105. ★ Review — Cataloging Wargame Techniques Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2 hours Prerequisites: you’ve solved Steps 96–104 (Bandit 0–30,…
-
Step 106. Linux Permissions Deep Dive — setuid, setgid, sticky bit
Step 106. Linux Permissions Deep Dive — setuid, setgid, sticky bit Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: rwx, ownership, and…
-
Step 107. Exploring Linux Logs — /var/log
Step 107. Exploring Linux Logs — /var/log Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2.5 hours Prerequisites: grep and find from Step 20, process…
-
Step 108. Environment Variables and PATH Injection
Step 108. Environment Variables and PATH Injection Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 2.5 hours Prerequisites: permissions and sudo from Steps 23–24, setuid…
-
Step 109. Symbolic Links and Hard Links — Another Name for a File
Step 109. Symbolic Links and Hard Links — Another Name for a File Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 2–3 hours Prerequisites: you’ve…
-
Step 110. Project: “The Gaps in Linux’s Permission Model” Reference Document — Reviewing Through an Attacker’s Eyes
Step 110. Project: "The Gaps in Linux’s Permission Model" Reference Document — Reviewing Through an Attacker’s Eyes Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time:…
-
Step 111. Installing Kali Linux — Setting Up the Attacker’s Workbench
Step 111. Installing Kali Linux — Setting Up the Attacker’s Workbench Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2–3 hours (excluding download time) Prerequisites:…
-
Step 112. Installing Metasploitable2 and Building the Isolated Lab — Completing a Safe Firing Range
Step 112. Installing Metasploitable2 and Building the Isolated Lab — Completing a Safe Firing Range Level 2 — Security Introduction and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 2–3 hours…
-
Step 113. Reconnaissance 1: A Complete Survey of the Target’s Services — Attacks Begin with Building a List
Step 113. Reconnaissance 1: A Complete Survey of the Target’s Services — Attacks Begin with Building a List Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty…
-
Step 114. Reconnaissance 2: Vulnerability Scanners and Reading Their Results — A Scanner Is a Candidate Generator
Step 114. Reconnaissance 2: Vulnerability Scanners and Reading Their Results — A Scanner Is a Candidate Generator Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty ★★★☆☆…
-
Step 115. How to Read a CVE: NVD and Exploit-DB — The Story Packed into a Single Number
Step 115. How to Read a CVE: NVD and Exploit-DB — The Story Packed into a Single Number Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty…
-
Step 116. Getting Started with Metasploit — The Standard Assembly Plant of Attacks
Step 116. Getting Started with Metasploit — The Standard Assembly Plant of Attacks Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty ★★★☆☆ | Estimated time: 3…
-
Step 117. ★ Your First Shell: Taking Over MS2 with the vsftpd Backdoor — Your Life’s First Remote Command Execution
Step 117. ★ Your First Shell: Taking Over MS2 with the vsftpd Backdoor — Your Life’s First Remote Command Execution Level 2 — Introduction to Security and the Basics of Attack Skills…
-
Step 118. Bind Shells vs. Reverse Shells — The Connection’s Direction Is Everything
Step 118. Bind Shells vs. Reverse Shells — The Connection’s Direction Is Everything Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty ★★★★☆ | Estimated time: 3…
-
Step 119. Mastering netcat — The Swiss Army Knife of Networking
Step 119. Mastering netcat — The Swiss Army Knife of Networking Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites:…
-
Step 120. Manual Exploitation 1: Attacking Without a Framework — Reproducing the Button’s Inner Workings by Hand
Step 120. Manual Exploitation 1: Attacking Without a Framework — Reproducing the Button’s Inner Workings by Hand Level 2 — Introduction to Security and the Basics of Attack Skills | Difficulty ★★★★☆…
-
Step 121. Manual Exploitation 2: Expanding Your Repertoire — Every Service Opens a Different Door
Step 121. Manual Exploitation 2: Expanding Your Repertoire — Every Service Opens a Different Door Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 4…
-
Step 122. Password Attack 1: hydra Online Brute Force — An Attack That Knocks on a Living Door
Step 122. Password Attack 1: hydra Online Brute Force — An Attack That Knocks on a Living Door Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ |…
-
Step 123. Password Attack 2: John the Ripper Offline Cracking — Stolen Hashes Break in Silence
Step 123. Password Attack 2: John the Ripper Offline Cracking — Stolen Hashes Break in Silence Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time:…
-
Step 124. Password Attack 3 — hashcat and Attack Modes
Step 124. Password Attack 3 — hashcat and Attack Modes Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: john and hash-format…
-
Step 125. Introduction to Privilege Escalation — From Shell to root
Step 125. Introduction to Privilege Escalation — From Shell to root Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3 hours Prerequisites: the setuid…
-
Step 126. Enumeration Automation — linPEAS
Step 126. Enumeration Automation — linPEAS Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: you’ve typed the six manual recon commands…
-
Step 127. The Post-Exploitation Checklist — The Beginning After the Shell
Step 127. The Post-Exploitation Checklist — The Beginning After the Shell Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 2 hours 30 minutes Prerequisites:…
-
Step 128. ★ Project — The MS2 Full-Compromise Report
Step 128. ★ Project — The MS2 Full-Compromise Report Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 4 hours Prerequisites: Steps 118–127 — the…
-
Step 129. Attacking Another VulnHub Vulnerable VM — Apply the Whole Routine to a Target You’ve Never Seen
Step 129. Attacking Another VulnHub Vulnerable VM — Apply the Whole Routine to a Target You’ve Never Seen Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ |…
-
Step 130. ★ Checkpoint: Time-Attack Mock Penetration — Run the Entire Process in 6 Hours
Step 130. ★ Checkpoint: Time-Attack Mock Penetration — Run the Entire Process in 6 Hours Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 7…
-
Step 131. Build Your Own Web Server — Login and Sessions
Step 131. Build Your Own Web Server — Login and Sessions Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: Step 94…
-
Step 132. Burp Suite 1: Intercepting with a Proxy — Slipping Between Browser and Server
Step 132. Burp Suite 1: Intercepting with a Proxy — Slipping Between Browser and Server Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2…
-
Step 133. Burp Suite 2: Repeater and Intruder — The Repeat Experiment Bench and the Automatic Machine Gun
Step 133. Burp Suite 2: Repeater and Intruder — The Repeat Experiment Bench and the Automatic Machine Gun Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ |…
-
Step 134. Cookie and Session Attacks — Shaking the ID Card the Server Trusts
Step 134. Cookie and Session Attacks — Shaking the ID Card the Server Trusts Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours…
-
Step 135. DVWA Setup and SQLi Basics — Crossing Low and Medium
Step 135. DVWA Setup and SQLi Basics — Crossing Low and Medium Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3.5 hours Prerequisites: SQL…
-
Step 136. SQLi Advanced — Dumping the Entire Database with UNION
Step 136. SQLi Advanced — Dumping the Entire Database with UNION Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3.5 hours Prerequisites: Step 135’s…
-
Step 137. Blind SQLi & sqlmap — Extracting Even When Nothing Shows
Step 137. Blind SQLi & sqlmap — Extracting Even When Nothing Shows Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3.5 hours Prerequisites: Step…
-
Step 138. XSS Basics — Reflected & Stored, the Traitor Inside the Browser
Step 138. XSS Basics — Reflected & Stored, the Traitor Inside the Browser Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3 hours Prerequisites:…
-
Step 139. XSS Advanced: Cookie Theft & Filter Bypass — Beyond alert, Stealing Sessions
Step 139. XSS Advanced: Cookie Theft & Filter Bypass — Beyond alert, Stealing Sessions Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 4 hours…
-
Step 140. CSRF: Request Forgery — The Victim’s Browser Clicks for You
Step 140. CSRF: Request Forgery — The Victim’s Browser Clicks for You Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3 hours Prerequisites: Step…
-
Step 141. File Upload Attack: Web Shell — From a Board Post to Server Takeover
Step 141. File Upload Attack: Web Shell — From a Board Post to Server Takeover Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 4…
-
Step 142. Web Shell Advanced: Writing Your Own & the Principles — Building the One-Line Door Yourself
Step 142. Web Shell Advanced: Writing Your Own & the Principles — Building the One-Line Door Yourself Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated…
-
Step 143. Command Injection — The Moment a Search Box Becomes the Server’s Terminal
Step 143. Command Injection — The Moment a Search Box Becomes the Server’s Terminal Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3 hours…
-
Step 144. File Inclusion: LFI/RFI — I Choose the File the Server “Reads for Me”
Step 144. File Inclusion: LFI/RFI — I Choose the File the Server "Reads for Me" Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3…
-
Step 145. Directory Busting & Information Exposure — The “If They Don’t Know the Address, It’s Safe” Fallacy
Step 145. Directory Busting & Information Exposure — The "If They Don’t Know the Address, It’s Safe" Fallacy Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ |…
-
Step 146. Authentication Attacks, Combined — Four Ways to Knock on the Front Door
Step 146. Authentication Attacks, Combined — Four Ways to Knock on the Front Door Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 4 hours…
-
Step 147. ★ DVWA All Difficulty Levels + the Three-Tier Summary Table — What It Means to “Completely” Know One Vulnerability
Step 147. ★ DVWA All Difficulty Levels + the Three-Tier Summary Table — What It Means to "Completely" Know One Vulnerability Level 2 — Introduction to Security and Attack Skill Basics |…
-
Step 148. OWASP Juice Shop 1: Introduction to the Modern Web App — The Attack Stage Has Changed
Step 148. OWASP Juice Shop 1: Introduction to the Modern Web App — The Attack Stage Has Changed Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ |…
-
Step 149. Juice Shop 2 — Access Control and IDOR
Step 149. Juice Shop 2 — Access Control and IDOR Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2.5 hours Prerequisites: Step 148 (Juice…
-
Step 150. Juice Shop 3 — JWT and Business Logic
Step 150. Juice Shop 3 — JWT and Business Logic Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: Step 149 complete.…
-
Step 151. Dreamhack Web Introduction — Your First Real Problems
Step 151. Dreamhack Web Introduction — Your First Real Problems Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2.5 hours Prerequisites: through Step 150…
-
Step 152. Dreamhack Web (Cumulative 16) — Recognizing Techniques in Disguise
Step 152. Dreamhack Web (Cumulative 16) — Recognizing Techniques in Disguise Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: Step 151…
-
Step 153. DreamHack Web (Running Total: 24) — Breaking Through with Research
Step 153. DreamHack Web (Running Total: 24) — Breaking Through with Research Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: Step…
-
Step 154. DreamHack Web (Running Total: 32) — Your Weakness List and Problem-Picking Strategy
Step 154. DreamHack Web (Running Total: 32) — Your Weakness List and Problem-Picking Strategy Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours…
-
Step 155. ★ Project — Independent Assault on a Vulnerable Web Target, with a Report
Step 155. ★ Project — Independent Assault on a Vulnerable Web Target, with a Report Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 4…
-
Step 156. MITM Primer — ARP Spoofing 1: A Protocol with No ID Card
Step 156. MITM Primer — ARP Spoofing 1: A Protocol with No ID Card Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours…
-
Step 157. ARP Spoofing 2 — Bidirectional Interception and the End of Plaintext
Step 157. ARP Spoofing 2 — Bidirectional Interception and the End of Plaintext Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 3 hours Prerequisites:…
-
Step 158. Packet Sniffing Advanced — The Two Faces of Filters and Reassembling Conversations
Step 158. Packet Sniffing Advanced — The Two Faces of Filters and Reassembling Conversations Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours…
-
Step 159. DNS Spoofing and bettercap — Swapping Out the Phone Book
Step 159. DNS Spoofing and bettercap — Swapping Out the Phone Book Level 2 — Network Attacks and MITM | Difficulty ★★★★☆ | Estimated time: 4 hours Prerequisites: Steps 156~157 (ARP spoofing)…
-
Step 160. SSL/TLS and HSTS — The ID-Card System That Stops the Man in the Middle
Step 160. SSL/TLS and HSTS — The ID-Card System That Stops the Man in the Middle Level 2 — Network Attacks and MITM | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites:…
-
Step 161. Firewalls and iptables — Designing the Gatekeeper’s Rules
Step 161. Firewalls and iptables — Designing the Gatekeeper’s Rules Level 2 — Network Attacks and MITM | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: Step 28 (port scanning) and Step…
-
Step 162. Proxies and Anonymity — The Art of Hiding Behind a Stand-In, and Its Limits
Step 162. Proxies and Anonymity — The Art of Hiding Behind a Stand-In, and Its Limits Level 2 — Network Attacks and MITM | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites:…
-
Step 163. SSH Tunneling and Port Forwarding — Loading Other Roads onto an Encrypted Passage
Step 163. SSH Tunneling and Port Forwarding — Loading Other Roads onto an Encrypted Passage Level 2 — Network Attacks and MITM | Difficulty ★★★★☆ | Estimated time: 4 hours Prerequisites: Step…
-
Step 164. Enumeration Tools, Complete Review — A System for Flipping Every Stone
Step 164. Enumeration Tools, Complete Review — A System for Flipping Every Stone Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites:…
-
Step 165. Password Spraying and Credential Stuffing — Attacks That Walk Sideways Past the Lock
Step 165. Password Spraying and Credential Stuffing — Attacks That Walk Sideways Past the Lock Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3…
-
Step 166. Wireless Security: WPA2 and the Handshake — Key Material Floating in the Air
Step 166. Wireless Security: WPA2 and the Handshake — Key Material Floating in the Air Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 2.5…
-
Step 167. Social Engineering: Hacking Humans — One Email That Bypasses the Firewall
Step 167. Social Engineering: Hacking Humans — One Email That Bypasses the Firewall Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2.5 hours Prerequisites:…
-
Step 168. Malware Structure: Trojans and Ransomware — Dissecting Without Building
Step 168. Malware Structure: Trojans and Ransomware — Dissecting Without Building Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 3 hours Prerequisites: Step 167…
-
Step 169. Encryption and Detection Evasion Concepts — The Arms Race Between the Hiders and the Seekers
Step 169. Encryption and Detection Evasion Concepts — The Arms Race Between the Hiders and the Seekers Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated…
-
Step 170. Introduction to OSINT — Social Media Collection and Digital Footprints
Step 170. Introduction to OSINT — Social Media Collection and Digital Footprints Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★☆☆☆ | Estimated time: 2 hours 30 minutes…
-
Step 171. OSINT Advanced — Subdomain and Asset Enumeration
Step 171. OSINT Advanced — Subdomain and Asset Enumeration Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 2 hours 30 minutes Prerequisites: the name-resolution…
-
Step 172. ★ Capstone Scenario 1 — From Recon to Shell
Step 172. ★ Capstone Scenario 1 — From Recon to Shell Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★☆ | Estimated time: 4 hours Prerequisites: Steps 113~119…
-
Step 173. Scenario 1 Review and Penetration Report — The Skill of Weaving Records into a Document
Step 173. Scenario 1 Review and Penetration Report — The Skill of Weaving Records into a Document Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated…
-
Step 174. Capstone Scenario 2: Web Intrusion → Internal Expansion — One Entrance Opens Everything
Step 174. Capstone Scenario 2: Web Intrusion → Internal Expansion — One Entrance Opens Everything Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★★★ | Estimated time: 6…
-
Step 175. Level 2 Comprehensive Assessment: The Attack/Defense Response Table — Completing Two-Sided Thinking
Step 175. Level 2 Comprehensive Assessment: The Attack/Defense Response Table — Completing Two-Sided Thinking Level 2 — Introduction to Security and Attack Skill Basics | Difficulty ★★★☆☆ | Estimated time: 5 hours…